EW-AiRM™ · The Book
Wiley Finance, 2026. A practitioner's framework for governing AI risk across the organisation, by Prof. Markus Krebsz. With forewords by Tobias Adrian, IMF, and Prof. Tshilidzi Marwala, Rector of the United Nations University.

Enterprise-Wide AI Risk Management (EW-AiRM™) opens with forewords from two of the world's most senior voices in financial stability and artificial intelligence.
Financial Counsellor and Director, Monetary and Capital Markets Department, International Monetary Fund
The Governance Imperative: Why Enterprise AI Risk Management Cannot Wait
In his foreword, Tobias Adrian describes artificial intelligence as having reached an inflection point: no longer a distant technology but one already embedded in credit decisions, fraud detection, compliance monitoring and increasingly autonomous agentic systems across the regulated financial sector. He argues that the efficiency gains are real, but so are new fragilities, from settlement risks that move faster than human oversight to concentration in infrastructure layers and deepening dependence on third-party providers whose failure modes are poorly understood.
Adrian highlights cybersecurity as a particularly acute concern, noting that AI has shifted the balance between attacker and defender and that AI-enabled attacks are now a deployed reality rather than a theoretical possibility. What has been missing, he writes, is the institutional-level answer: a framework that translates macro-level concern into governance practice for the risk professionals actually responsible for deployed AI systems. In his assessment, this book provides precisely that. He describes EW-AiRM™ not as an ethics overlay or a compliance checklist, but as a genuine augmentation of the enterprise risk management architecture regulated organisations already have, extending the ERM tradition into territory it was never equipped for. He singles out the three-layer structure, the eight-category AI Black Swan framework, the continuously operating HAiPECR ethical filter and the five non-negotiables as features of particular value from a financial stability perspective, and praises the book's candour in acknowledging that the risk landscape evolves faster than any printed framework can capture. While his vantage point is regulated finance, he stresses that the governance architecture is sector-agnostic and universal in ambition: proportionate to any organisation, from a globally systemic institution to a first-time deployer of a single AI tool.
The views expressed are those of the author and do not necessarily represent the views of the IMF, its Executive Board, or its Management.
Rector, United Nations University; Under-Secretary-General of the United Nations
Professor Tshilidzi Marwala, who has worked in artificial intelligence for more than thirty years, writes that the current speed of AI deployment relative to institutional readiness to govern it is qualitatively different from any previous period in the technology's development. The problem, he argues, is structural: existing risk frameworks assume deterministic systems, traceable failures and assignable accountability, and generative AI violates each of these assumptions.
Marwala writes that extending enterprise risk management to cover probabilistic, emergent AI behaviour in a principled and operationally serious way is genuinely difficult work, and that this book does that work. He notes that EW-AiRM™ is not another set of principles (the field already has more principles than it can act on) but a structured governance architecture that translates strategic intent into working instruments: pre-deployment safety cases, named accountability, tested human override capability, continuous monitoring and a control library drawn from systematic analysis of over eight hundred evidence-based mitigations. He engages seriously with two open challenges for the field: the question of institutional will, where competitive incentives push organisations to treat governance as overhead, and the question of whose governance this is, given that frontier AI is built by a handful of organisations while the consequences of ungoverned deployment often fall hardest on the Global South. He describes the book's treatment of governance theatre as among the most precise he has read, and concludes that for the risk professional seeking a framework that is rigorous, operationally grounded and built on evidence rather than aspiration, it is a comprehensive resource.
Both forewords appear in full in Enterprise-Wide AI Risk Management (EW-AiRM™), published by Wiley.
Enterprise-Wide AI Risk Management (EW-AiRM™) has been endorsed by leaders across policy, regulation, financial services, academia, AI ethics and technology.
As the chair of the original House of Lords Select Committee on Artificial Intelligence, I have long argued for good AI governance - and EW-AiRM delivers exactly that. Professor Markus Krebsz has built a rigorous, practitioner-ready architecture that speaks the language risk professionals actually use, anchored in UNESCO's ethical framework and the international regulatory instruments he helped design. For any board, CRO or compliance officer serious about closing the gap between the appearance of AI governance and its reality, this is the book they need.
Lord Clement-Jones CBE
LibDem Lords spokesperson for Science, Innovation & Technology; Author of "Living with the Algorithm"
Drawing on deep expertise in governance, risk, and emerging technologies, Prof. Krebsz offers a thoughtful approach to enterprise-wide AI risk management. Combining rigorous analysis with practical guidance, this book is valuable reading for anyone seeking a deeper understanding of AI risks and enhanced capabilities to manage them while harnessing AI's transformative potential.
Heidi M-B Lund
Expert on International Regulatory Cooperation; UNECE WP.6 Chair (2021–2025)
As enterprises delegate ever more consequential decisions to AI, the discipline of governing those systems must keep pace with their capability. Markus Krebsz brings the practical scaffolding to help boards and risk functions. This is a rigorous, usable guide to closing the gap between principle and practice, and it earns its place on every risk leader's desk.
Colin Payne
Head of Innovation, Financial Conduct Authority (FCA); Chairman, Global Financial Innovation Network (GFIN)
The publication Enterprise-wide AI Risk Management (EW-AiRM™) by Professor Markus Krebsz constitutes a timely and eminently practical contribution to the advancement of responsible artificial intelligence governance. By equipping organizations worldwide with a robust three-layer framework, together with the innovative HAiPECR ethical filter, the book promotes accountable, equitable and sustainable AI deployment in full alignment with the objectives of the United Nations University Global AI Network (UNU Global AI Network), thereby supporting the United Nations system-wide commitment to multilateral cooperation, human-centred AI governance, and the realization of the Sustainable Development Goals.
Dr. Jingbo Huang
Director, United Nations University Institute in Macau (UNU Macau)
As intelligence converges across human and artificial domains, Krebsz delivers what the moment demands: not abstract theory, but a governance instrument for the age of superintelligence. The window to shape AI for humanity is closing—this framework is how we keep it open.
Amb. Dr. Lavina Ramkissoon (aiMOM)
African Union, United Nations, European Union and ITU
Copyright © 2026 Ambassador Lavina Ramkissoon. Reproduced with attribution.
If you are looking for concrete ways to govern AI risks responsibly, ethically and safely within your organization, this is the ideal book for you! Prof. Markus Krebsz has clearly translated his extensive and successful work in this field into this book, presenting a framework anchored on international standard-setting instruments like the UNESCO Recommendation on the Ethics of Artificial Intelligence—the world's first global normative framework adopted by acclamation by UNESCO Member States.
Edson Prestes
Full Professor, Institute of Informatics, Federal University of Rio Grande do Sul, Brazil; Chair, IEEE RAS/SA 7007 and 7007.1 Working Groups; Former Member of the UN Secretary-General's High-level Panel on Digital Cooperation; Former Member of the UNESCO AHEG for the Recommendation on the Ethics of AI
Markus Krebsz combines deep risk expertise and scholarly rigor to deliver a sophisticated, enterprise-wide framework for managing AI-risk-related challenges. By augmenting established ERM principles with multi-layered approach and ethical filter, EW-AiRM transforms AI risk management into practical, integrated solutions. This is essential reading for risk professionals, executives, board members, and regulators.
Bob Mark
Managing Partner, Black Diamond; Co-author of "The Essentials of Risk Management, Third Edition"
Good AI governance keeps a human at the centre, by design, not as an afterthought. Krebsz builds that conviction into structure, placing human oversight at the heart of every AI decision rather than bolting ethics on at the end. EW-AiRM is rigorous, board-ready, and refreshingly honest about what governance theatre costs us.
Dr. Martha Boeckenfeld
Human-Centric Futurist; Board Director, Insurance & Asset Management
EW-AiRM offers senior risk leaders a practical, enterprise-wide approach to governing AI, focused on explainability, lifecycle monitoring, human oversight and operational resilience. Among its clearest contributions is treating agentic and multi-agent systems as ongoing control problems rather than one-off implementations, making it immediately actionable for boards, CROs and risk teams.
Tanveer Bhatti
Former Managing Director and Global Head of Model Risk and Valuation Control, Citi; former Head of Group Model & AI Risk Management, Revolut
Krebsz writes with the rare honesty AI governance needs: clear about what EW-AiRM™ can resolve and equally clear about what it can't. Grounded in MIT's risk taxonomy and the author's own multilateral track record, it gives risk practitioners genuinely usable structure, not just another framework promising more than it can deliver
Ratul Ahmed
Divisional Board Member, Model Risk Management & Validation, Commerzbank AG, Group Risk Management
Boards can no longer rely on existing structures to address emergent AI risks, as engineered systemic change is constantly shifting with complex AI systems in operation. AI-assisted decisions and actions have real-world consequences and require immediate attention. Krebsz's insights and comprehensive framework illuminate the path forward through effective risk management, human oversight and strong ethical leadership.
Maria Santacaterina
Strategic Board Advisor; Author, "Adaptive Resilience: How to thrive in a digital era" (Wiley)
As AI becomes embedded in organizational decision-making, governance needs to become more practical, measurable, and accountable. EW-AiRM provides a useful framework for that transition, connecting enterprise risk management with AI risk identification and mitigation in a format designed for practitioners.
Peter Slattery, PhD
Research Scientist, MIT AI Risk Initiative, MIT FutureTech
AI risk is not well understood or appreciated. It is rearing its head in many ways and in many places. We have witnessed how employees, and even leaders, are cutting corners and getting AI to do their job, or failing to check the results AI produces. This has caused significant embarrassment to firms like Deloitte and KPMG. It has seen highly experienced trial lawyers (Barristers) producing briefs with "hallucinated" citations. While AI represents extraordinary opportunities, it also represents grave risks. This book addresses these risks for enterprises for the first time. It should be regarded as indispensable.
Dr Andy Schmulow
Associate Professor, School of Law, University of Wollongong, Australia; Visiting Associate Professor, Mandela Institute, University of the Witwatersrand, Johannesburg
Mr. Markus Krebsz has crafted an indispensable resource that arrives precisely when society and the business ecosystem need it most. A rigorous, comprehensive, and masterfully structured book every responsible leader must read.
Prof. Dr. Ingrid Vasiliu-Feltes
University of Miami, FL, USA
EW-AiRM addresses a critical gap: as AI moves into physical environments, including embodied and multimodal systems, robotics, edge computing and sensing infrastructure spanning automated industrial lines, autonomous mobility and city-scale technologies, enterprise risk frameworks must evolve beyond software-only models. Built on the MIT AI Risk Repository and aligned with EU and OECD governance architecture, the book provides the operational depth that practitioners deploying AI in cyber-physical environments need.
Yonah Welker
Visiting Technologist & Lecturer, MIT — Embodied AI & Advanced Robotics; Evaluator & Rapporteur, EU Horizon / EIT / EIC
A thoughtful, systemic and comprehensive approach to navigating the complex intersection of AI, governance, organizational culture, and human psychology, a must read for anyone working on implementing a sustainable approach to AI in their organization
Alison Taylor
Clinical Associate Professor at NYU Stern and author of Higher Ground
Prof. Krebsz has written an essential roadmap for AI risk practitioners at all levels to govern and manage risk effectively. Practical questions and concrete next steps make it actionable. In my affiliated AI programs, we reference maturity frameworks constantly — none are as well-articulated as the one in this book.
Peggy Tsai
AI & Data Executive Leader; Faculty Instructor at Carnegie Mellon University and University of Denver
Artificial Intelligence, especially when deployed with agency, is completely altering the fabric of risk management at the enterprise level. EW-AiRM™ is a powerful new framework that integrates seamlessly with most process-specific and/or product-specific risk management for AI. EW-AiRM™ empowers the C-suite to confidently and comprehensively govern the deployment of AI.
Ryan Carrier
Executive Director, ForHumanity
Krebsz demonstrates how the harm from poor governance is not proportionate to organisational size, and that "governance theatre" simply fails us! EW-AiRM puts into practice an AI governance framework that is workable and cross-jurisdictional. By anchoring HAiPECR to UNESCO's principles and treating human override and mitigation of "AI laziness" as non-negotiables, Krebsz turns ethics from a bolt-on, into a discipline working alongside trusted legal and human rights advisors, which is scalable from sole practitioner to enterprise.
Patricia Shaw
CEO of Beyond Reach Consulting Limited, Global AI Governance Advisor, and UK&I Solicitor
Markus's book offers a clear and well-structured framework for guiding discussions on risk management in the age of Artificial Intelligence (AI). Rather than presenting definitive solutions, it provides a common language, useful categories, and practical reference points that can help organisations and practitioners start the discussion on complex issues with greater clarity.
Enrico Panai
President of the Association of AI Ethicists; Convenor of Foundational and societal aspects of AI at CEN-CENELEC JTC21; Project leader of AI-enhanced nudging at ISO/IEC JTC1 SC42; Professor at UNICATT
EW-AiRM makes a strong case that traditional risk frameworks are inadequate for the fast-paced, probabilistic features that characterize today's AI. The critique of the Three Lines of Defence model is particularly valuable for any risk professional still trying to fit AI governance into legacy structures.
Reid Blackman
Author, "The Ethical Nightmare Challenge" and "Ethical Machines"; Founder and CEO, Virtue
Professor Krebsz's book distills years of risk management expertise and know-how into a practical guidance. Probabilistic systems. combined with evolving capabilities, make AI governance a must-have function. Enterprises would benefit from following his maxims.
Merve Hickok
Founder - AIethicist.org
Krebsz names governance theatre directly and identifies the firms most likely to produce documentation in place of control. He insists that oversight be tested under pressure before it is trusted. A practitioner's instrument for anyone asked to govern AI, written without illusions about how oversight fails.
Richard Foster-Fletcher
Chair of MKAI
I like EW-AiRM because it is unusually well-tailored for practitioners with grounding in the MIT AI Risk Repository, governance reality, and competing incentives. So much practical risk management lives in the gap between "can we?" and "should we?" and HAiPECR lands the right questions at every decision point.
Sarah Clarke
Infospectives Ltd
Thoughtful and thorough: a comprehensive handbook for the AI risk professional. Human-crafted with AI assistance, exemplifying how to use AI as a valuable tool.
Ray Eitel-Porter
Author of "Governing the Machine: How to navigate the risks of AI and unlock its true potential"
In my assessment, Enterprise-Wide AI Risk Management (EW-AiRM™) represents a meaningful contribution to the evolving discipline of AI governance. It offers a practical perspective informed by real-world risk management experience and provides organizations with a structured methodology for addressing challenges that will increasingly define the next generation of enterprise leadership.
I reviewed the selected chapters of Enterprise-Wide AI Risk Management (EW-AiRM™) with particular interest in the sections addressing AI governance, systemic risk, operational resilience, and quantum-era security implications. Prof. Markus Krebsz has produced a thoughtful and ambitious framework that seeks to bridge a significant gap between traditional enterprise risk management practices and the emerging realities of artificial intelligence. Rather than presenting AI as a standalone technology challenge, the EW-AiRM™ framework treats AI as an enterprise-wide governance issue requiring strategic alignment, operational discipline, accountability, resilience, and continuous oversight. One of the book's greatest strengths is its practitioner-oriented approach. The framework is not limited to ethical principles or high-level policy discussions. Instead, it provides a structured architecture designed to help organizations operationalize AI governance through clearly defined layers, assessment dimensions, control mechanisms, and implementation pathways. This practical orientation makes the work particularly relevant for executives, risk professionals, board members, regulators, and technology leaders. I was especially interested in the treatment of systemic and low-probability, high-impact events, including the discussion of AI Black Swan risks and quantum cryptographic transition. Having spent part of my career responsible for highly sensitive national-level communications infrastructure, I found the author's emphasis on resilience, accountability, and long-term governance preparedness both relevant and timely. The recognition that quantum computing presents not merely a technical challenge but a strategic governance challenge reflects an understanding that many organizations have yet to fully appreciate. Another noteworthy aspect of the manuscript is the author's transparency regarding the use of AI-assisted tools during the writing process. Rather than diminishing the work, this disclosure reinforces the governance principles advocated throughout the book by demonstrating accountability, oversight, and responsible use of emerging technologies. The book's central contribution is its attempt to integrate AI governance, enterprise risk management, operational resilience, ethics, and emerging technology risks into a single coherent framework. Whether every element ultimately becomes an industry standard remains to be seen, but the framework provides a serious and valuable foundation for discussion, implementation, and future refinement. In my assessment, Enterprise-Wide AI Risk Management (EW-AiRM™) represents a meaningful contribution to the evolving discipline of AI governance. It offers a practical perspective informed by real-world risk management experience and provides organizations with a structured methodology for addressing challenges that will increasingly define the next generation of enterprise leadership.
John Keith King
Former Lead Engineer, U.S. Presidential Direct Communications Link; Enterprise Architect and Strategic Technology Advisor
Endorsements are reproduced with the permission of their authors and reflect their personal views, not necessarily those of their affiliated organisations. Enterprise-Wide AI Risk Management (EW-AiRM™) is published by Wiley. EW-AiRM™ is a trade mark of De-Risking Solutions Ltd.
One email when the book is published. Optionally, the quarterly framework update. No other use of your address.
The Human-Ai.Institute is an independent Think/Do Tank convening multilateral and multi-stakeholder dialogue on AI governance. The Institute engages with the UN, UNESCO, OECD, the EU Commission, and governments worldwide.
Home of EW-AiRM™ — the open, three-layer framework for enterprise-wide AI risk management, grounded in publicly licensed standards and aligned with UNESCO, UNECE, NIST, ISO, and the EU AI Act.
Commercial consulting, training, and advisory services are provided by De-Risking Solutions Ltd. and RiskAi.Ai
AI & TECHNOLOGY SOLUTIONS
AI, Agentic tools and technology solutions are provided by Human-Ai.Solutions.
The Human-Ai.Institute
is run and maintained by
De-Risking Solutions Ltd.
Email:
contact [at] human-ai.institute
Listed on the OECD AI Policy Observatory · Founding member of the UN University AI Network · Aligned with UNESCO, UNECE WP.6, NIST, and ISO 42001
EW-AiRM™ and HAiPECR™ are trademarks of De-Risking Solutions Ltd., registered in England and Wales (Company Number 09900565). All rights reserved.
© 2026 The Human-Ai.Institute.